
One challenge with Classic policies is that Citrix Workspace app requires the LDAP and RADIUS fields to be swapped. This is the older method of configuring authentication also known as Classic authentication policies.This functionality is available in all ADC Editions and is detailed in this post. Citrix Gateway Virtual Server has bind points for Primary and Secondary authentication.CTX203775 Dual Password Field wrongly shows in First Authentication Prompt when connecting to NetScaler Gateway using ReceiverĪDC has two methods of configuring multi-factor authentication:.Receiver 4.4 and newer supports hiding the 2nd field if you configure a Meta tag in index.html. SMS Passcode) require you to hide the 2nd password field. Citrix CTX125364 How to Configure Dual Authentication on NetScaler Gateway Enterprise Edition for Use with iPhone and iPad.

For two-factor authentication using Azure Multi-factor Authentication, see Jason Samuel How to deploy Microsoft Azure MFA & AD Connect with Citrix NetScaler Gateway.Use the same RADIUS Secret for both appliances. However, if you are not locally load balancing RADIUS, then you’ll need to add the NSIP of both appliances as RADIUS Clients. For High Availability pairs, if you locally load balance RADIUS, then you only need to add the SNIP as a RADIUS Client, since the SNIP floats between the two appliances.Use the correct IP(s) when adding the ADC appliances as RADIUS Clients. When ADC uses a direct connection to a RADIUS Server without going through a load balancing Virtual Server, or uses a remote (different appliance) Load Balancing Virtual Server, the traffic is sourced from the ADC NSIP (ADC Management IP). When ADC uses a local (same appliance) load balanced Virtual Server for RADIUS authentication, the traffic is sourced from the ADC SNIP (Subnet IP). RADIUS Clients and Source IP – On your RADIUS servers, you’ll need to add the ADC appliances as RADIUS Clients. SAML is detailed in the Federated Authentication Service article. Another common two-factor authentication method is SAML to an Identity Provider, like Azure Active Directory or Okta.One method of two-factor authentication to Citrix Gateway is the RADIUS protocol with a two-factor authentication product (tokens) that has RADIUS enabled.

2019 Jun 17 – Create RADIUS Server – change password encoding to mschapv2.2021 Mar 29 – added Advanced (nFactor) Two-factor Policies.

